There has been a request for the creation of a single OWASP-wide vulnerability reporting mailing list, OWASP-alerts, so that corporations can monitor for vulnerabilities in our software. This is a PCI requirement. The items posted here would be security vulnerabilities in our libraries (ESAPI, AntiSamy, Encoding, and maybe our tools). Assuming we support the idea, we need to decide who would moderate the list.

Proposal - OWASP should move off of mailman and onto groups.owasp.org

This brings the full power and ease of administration of Google Groups to an OWASP domain. The existing archives have been uploaded to Google docs where anyone can search them. The only real hiccup is that people must have a google account to use this (or an owasp.org account). We can force add all existing members and their transition to the new list should be seamless - this will get them email list functionality. If they want the full forum, they'll need to have a google account. One other hiccup is that OWASP-ALL will generate one email per list. We can manage a list of lists, but any message will get multiplexed across all of them. Ideas?